Skip to content

Privacy and preparation

How to verify that a buyer deleted your data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

To verify that a buyer deleted your data, agree a ladder of proof in the license before delivery: a written attestation, a signed certificate of destruction listing every copy, an audit right you can exercise, and technical evidence such as revoked access or a destroyed key. The strongest proof is access you control yourself.

Key takeaways

  • You cannot see inside a licensee's systems, so the form of deletion proof has to be agreed in the license before delivery.
  • A certificate of destruction should list each copy and derivative, the method, the date and an accountable signer.
  • Deleting dataset copies and retiring trained models are separate obligations and need separate wording.
  • Access you control, such as expiring credentials to data kept in your own storage, gives the clearest proof.
  • File every certificate with the license so a future acquirer or auditor can follow the record.

The verification ladder: from attestation to technical evidence#

The verification ladder runs from a buyer's word to evidence you can check yourself, and each rung adds assurance and effort. No rung lets you watch another company's systems directly, so the realistic goal is an accountable signer at minimum and independent confirmation where the package warrants it.

Match the rung to the package. A de-identified set of order exceptions calls for less than a package carrying customer names or source code, and many licenses combine the first two rungs by default while reserving the third and fourth for higher-risk packages or for cause.

Pick the rung when you scope the package, not when the term ends. A buyer that agreed to an audit right at signing will expect it; one asked for an audit after the fact may reasonably refuse.

The verification ladder: from attestation to technical evidence
RungWhat you receiveWhat it showsLimit
AttestationA written statement that deletion is completeThe buyer accepts responsibility in writingNo detail on which copies were checked
Certificate of destructionA signed document listing copies, methods and datesAn accountable officer verified named itemsRelies on the buyer's own inventory
Audit rightInspection by you or an independent assessorSomeone outside the buyer examined systems and recordsEffort and cost, so often limited to cause
Technical evidenceRevoked access, key destruction records, deletion logsData became unreadable in a way systems recordedStrongest when you control the key or the access

Where copies hide inside a licensee#

Copies hide wherever data was moved, transformed or backed up after delivery, and a credible certificate names each location. Ask for the licensee's data handling map at signing, so you know what the certificate should cover when the time comes.

Backups need explicit handling. Purging one dataset from backups is often impractical, so licenses commonly let backups expire on their normal cycle, as long as nobody restores the data or reads from those backups before they expire.

  • The delivered package itself: drives, download folders and landing buckets.
  • Working copies in storage used for cleaning, filtering or labeling.
  • Derived datasets, such as tokenized, deduplicated or reformatted versions of your records.
  • Evaluation and test sets carved out of the package.
  • Copies held by contractors, labeling vendors or permitted sub-licensees.
  • Backups and snapshots that roll off on their own schedule.
  • Exports on laptops or in notebooks used by individual researchers.

What a deletion certificate should contain#

A deletion certificate should let someone who never saw the deal match it to the license and to the delivery. Vague certificates that say only that all data has been deleted are common, and they are hard to rely on when a question surfaces years later.

Send the buyer the element list below with the deletion notice. Asking for a specific format up front is easier than chasing missing details after a certificate arrives.

What a deletion certificate should contain
Certificate elementExample content
License and package referenceAgreement name, package identifier, delivery date
ScopeOriginal package, working copies, derived datasets, contractor copies
MethodLogical deletion, cryptographic erasure or physical destruction, by location
BackupsWhere backups exist and when they expire
ExceptionsAnything kept under the license, such as trained models, and why
SignerNamed officer with authority, date and signature
Sub-licenseesConfirmation that permitted recipients deleted their copies too

Trained models are a separate question#

Trained models are a separate question from deleted copies because a model stores patterns learned from your records rather than the records themselves, so there is no file to point at and erase. Retraining without your package is the only certain way to remove its influence, and that has to be negotiated explicitly rather than assumed.

Decide what you need before signing. Options include letting models trained during the term survive, barring new training after the term ends, requiring retirement of models built mainly on your package, or limiting outputs that reproduce your records. Whatever the choice, the certificate should state it as a named exception rather than leave it unsaid.

Technical evidence you can check yourself#

Technical evidence is strongest when the supplier, not the buyer, controls what makes the data readable. If the buyer works on data kept in your storage through scoped, expiring credentials, ending access is something you do and log yourself.

Key-based approaches work the same way for copies that stay encrypted. When a package is delivered encrypted and the key sits in a key management service under your control or in escrow, revoking or destroying the key leaves those copies unreadable, and the service's logs show when it happened. Decrypted working copies are not covered, so they still need deletion and a line in the certificate.

Where the buyer's systems produce them, ask for supporting logs alongside the certificate: storage deletion events, retention policy changes and the ticket from the team that ran the deletion.

Illustrative: a consulting firm closes out a license#

Illustrative: a fictional management consulting firm licensed a de-identified package of proposals, project review notes and internal playbooks for a fixed term. The license required a certificate of destruction at term end and gave the firm an audit right exercisable for cause.

When the term ends, the firm's general counsel sends a deletion notice quoting the package identifier. The certificate that comes back lists the landing bucket, two derived datasets and a labeling contractor's copy, says backups expire on the buyer's normal cycle, and records that models trained during the term survive, as the license allowed.

Counsel compares the certificate with the data handling map from signing, notices that an evaluation set is missing, and asks for a corrected certificate rather than invoking the audit. The corrected version is filed with the license and the release authorization.

How SourceX approaches deletion verification#

Deletion terms and the level of proof are settled at Approval, the fourth stage of the SourceX five-step transaction, so they are fixed before Delivery. The supplier decides what proof each package needs, and large datasets can stay in the supplier's own storage, which keeps access under the supplier's control.

Permitted use and release authorization in the SourceX Evidence Packet record what the buyer may do with the package and for how long, which gives the deletion certificate a clear reference point when the term ends.

Frequently asked questions

Is a deletion attestation legally meaningful?

An attestation is a written representation, and if it proves false the license's remedies apply. It gives you a basis to act rather than proof. Its value rises when the license makes it an officer's responsibility, ties it to a defined scope and pairs it with an audit right.

What if the buyer is acquired during the license?

Check the assignment clause first, since many licenses let the data pass to an acquirer only with consent or on the same terms. Ask for written confirmation of who now holds the package and that the deletion obligations carry over, and file it with the license.

Who at the buyer should sign the certificate?

An officer with authority over the systems that held the data, such as a head of data, security or legal, rather than the researcher who used it. The license can name the role. A signer with real accountability is more likely to check the full list of locations before signing.

How long should we keep deletion certificates?

Keep them at least as long as the license records themselves, since they are the evidence that the obligations ended. Counsel can set a period that fits your other contract records. A certificate earns its keep years later, in diligence or in answer to a customer question, when nobody remembers the delivery.

What if a copy turns up after the certificate was signed?

Treat it as a breach of the license and require prompt deletion, a corrected certificate and an explanation of how the copy was missed. The certificate's list of locations shows which part of the buyer's process failed and whether other copies could exist.

Can we audit a buyer without cause?

Only if the license allows it. Some licenses give a periodic audit right; others allow audits only for cause, such as a credible report of misuse. Independent assessors are common, because buyers often prefer that a supplier not inspect their systems directly.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify